Elasticsearch & Full Text Search Systems · Leçon

Clés d’API et journalisation d’audit

Sécurisez l’accès programmatique avec des clés d’API limitées à un périmètre plutôt qu’avec des mots de passe, et établissez qui a fait quoi en activant et en consultant le journal d’audit Elasticsearch.

Leçon 4 sur 413 étapes

Clés d’API et journalisation d’audit est une leçon Elasticsearch & Full Text Search Systems gratuite sur CoddyKit. Ceci est la leçon 4 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Elasticsearch & Full Text Search Systems, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Elasticsearch & Full Text Search Systems comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Beyond Passwords

Applications should not authenticate with a human's username and password. Elasticsearch provides API keys: scoped, revocable credentials ideal for services. Pair them with audit logging to track every security-relevant action.

What Is an API Key

An API key is a credential tied to a set of permissions, with an optional expiration. It can be limited to a subset of the creating user's privileges, following the principle of least privilege.

Creating a Key

Use the create API key endpoint. The response includes an id and api_key value shown only once, so store it securely.

POST /_security/api_key
{
  "name": "logging-app",
  "expiration": "30d"
}

Restricting a Key

Attach role_descriptors to limit what the key can do, even if the creating user has more power. Here the key may only read one index.

POST /_security/api_key
{
  "name": "reader",
  "role_descriptors": {
    "ro": {
      "indices": [{ "names": ["logs-*"], "privileges": ["read"] }]
    }
  }
}

Using a Key

Send the base64-encoded id:api_key pair in the Authorization header with the ApiKey scheme.

GET /logs-2024/_search
Authorization: ApiKey VnVhQ2ZHY0JDZGJrU...

Revoking Keys

Compromised or retired keys are invalidated immediately, without changing any user's password. You can revoke by id, by name, or all keys owned by a user.

DELETE /_security/api_key
{
  "name": "logging-app"
}

Why Audit Logging

Audit logs answer the compliance question: who did what, when, and from where. They record authentication attempts, access grants and denials, and configuration changes.

Enabling the Audit Log

Audit logging is turned on in elasticsearch.yml. It is disabled by default because it generates significant volume.

xpack.security.audit.enabled: true

Filtering Events

Tune which events are captured with include/exclude lists to avoid drowning in noise. Common choices keep access_denied and authentication_failed while dropping routine reads.

xpack.security.audit.logfile.events.exclude: [ access_granted ]

Reading Audit Output

Audit events are written as structured JSON to a dedicated log file. Each line includes the event type, user, client IP, request path, and outcome, making it easy to ship into Kibana for analysis.

Best Practices

Rotate API keys regularly, scope them tightly, store the audit log on durable storage separate from the cluster, and alert on repeated authentication_failed events that may signal an attack.

Quick Check

Test your understanding of API keys.

Recap

You learned to secure access and accountability:

  • API keys are scoped, expiring, revocable credentials for applications.
  • Use role_descriptors to enforce least privilege.
  • Audit logging records who did what, when, and from where.
  • Filter audit events to manage volume and alert on failed authentications.
Gratuit pour commencer

Apprends Elasticsearch & Full Text Search Systems avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
12
Leçons
48

Questions Fréquemment Posées

La leçon « Clés d’API et journalisation d’audit » est-elle gratuite ?

Oui — le texte complet de « Clés d’API et journalisation d’audit » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Elasticsearch & Full Text Search Systems, passe à CoddyKit PRO. Le cours Elasticsearch & Full Text Search Systems comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Clés d’API et journalisation d’audit » ?

Sécurisez l’accès programmatique avec des clés d’API limitées à un périmètre plutôt qu’avec des mots de passe, et établissez qui a fait quoi en activant et en consultant le journal d’audit Elasticsea… Tu pratiques Elasticsearch & Full Text Search Systems avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer Elasticsearch & Full Text Search Systems ?

Aucune expérience préalable n'est requise. Elasticsearch & Full Text Search Systems sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 4 sur 4.

Combien de temps prend la leçon « Clés d’API et journalisation d’audit » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon Elasticsearch & Full Text Search Systems ?

Oui. Chaque leçon Elasticsearch & Full Text Search Systems inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Authentification des utilisateurs et rôles
  2. Sécurité au niveau des champs et des documents
  3. TLS/SSL et sécurité réseau
  4. Clés d’API et journalisation d’audit
← Retour à Elasticsearch & Full Text Search Systems